We use the MITRE ATT&CK framework at my infosec consulting company quite heavily. It's the structure we use to define security content, allowing us to use the same language with our clients that auditors do, and allowing us to use the same language between customers to assess client- or industry-specific threats across all of our customers.
Having a high level framework to discuss threat helps, but so does the process of laying out all the possible threats. It's a kind of checklist, have I secured this properly? Have I thought about all the attack vectors?
I hope these MITRE-style attack matrices catch on more.